Live data from Hacker News

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

threatpost.com

71–80 of 424 posts

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#71
post #65

Earlier quoted context omitted.

This is just my opinion, based on my experience and personality. Voice first running entirely on prem with no internet connectivity, sure I would go for that. Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications.

I guess you’ll have to wait another decade or two. In the meantime, I’m “feeding” my devices every day. Hopefully voice-first becomes a solved problem, and you’ll get your device sooner.

What's funny about that is, I had voice recognition software in 1991 that could start up any application on my computer, reboot my computer, etc. Surely there must be a small device with the processing power of my old 386-DX40.

I believe it was made by a company called Covox or something? There were several other companies that made similar software back then.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#72
post #48

Earlier quoted context omitted.

1) It's always listening for a keyword, and then it starts recording. It's a voice interface for a computer. 2) Your phone is doing the same thing except for it follows you around everywhere you go and records your map location, what apps you use, who you are talking to and what your web searches are. Your phone isn't recording just what you say...its recording what you do and where you do it and when you do it. It's…

I get 1) and 3), but I don’t buy 2). Your phone works with Siri/any other assistant off. The connected speakers don’t. So the comparison doesn’t hold in my opinion.

You can just mute the connected speakers and it's the same as having Siri off. Or get one of the ones that requires you to push a button (the Amazon Tap).

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#73

Earlier quoted context omitted.

1) It's always listening for a keyword, and then it starts recording. It's a voice interface for a computer. 2) Your phone is doing the same thing except for it follows you around everywhere you go and records your map location, what apps you use, who you are talking to and what your web searches are. Your phone isn't recording just what you say...its recording what you do and where you do it and when you do it. It's…

1) Nobody can prove that. It's always listening and you have to assume always recording and transmitting. 2) My phone is a $12 throw away that speaks voice and sms (text). 3) Loose lips sink ships.

If we are playing the "you can't prove that" game, then you also can't prove that your $12 throw away phone isn't always recording, or that you new kitchen countertop doesn't have a recording device embedded in it, or that the maker of whatever device you are using to type that comment isn't breaking a plethora of laws to record everything you type or say or do around that device at any time.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#74

Earlier quoted context omitted.

> Nobody can prove that. It's always listening and you have to assume always recording and transmitting Uh... packet analyzers, IP logs, bandwidth monitoring tools etc... If instead of transmitting occasional bursts of data when you say the wake word it's been sending back tens of megabytes an hour, or tens to hundreds of megabytes a day, you can go "hey, it's probably transmitting everything it hears". There are peo…

Which nobody can do. It is encrypted and unless the device accept invalid certs, they can queue up, compress, batch upload any data they want. They control the security, not the end-luser.

Encrypted or not, an audio stream should not be difficult to identify.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#75
post #19

Earlier quoted context omitted.

that makes sense. though I wonder if for training purposes they can simply remove the user identifier. (like anonymizing them for instance)

Nothing in the article suggests they were linked to any kind of user identifier, all we know is that each recording is linked to the transcription alexa made of it (which makes sense, training and log wise). The user were easy to identify because if I listen to the last twenty queries you made to alexa between what you ask, what other people say in the background, what you talk about and what noise is in the backgrou…

> Nothing in the article suggests they were linked to any kind of user identifier

They were able to provide the customer a bundle of his recordings upon request so they must've maintained such a lookup mapping.

Of course that led to the mix up reported here. But I'd argue it's safer if on Amazons side they simply can't fulfill such request themselves due to anonymization.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#76
post #59
post #24

Earlier quoted context omitted.

The only company I've seen take demonstrable action to protect their customer's privacy is Apple. Google, Facebook, Microsoft, Amazon have never given me a single reason to trust that they have my privacy concerns on their mind.

But with Apple's entire ecosystem being closed and intentionally locking you in, is Apple really a better choice. All it takes is one decision from the board that it would be more profitable to start violating privacy. The board's legal mandate is to make as much money as possible. As soon as privacy is no longer a fad that makes more money and growth than the opportunity cost to not violating it, Apple will flip a s…

> The board's legal mandate is to make as much money as possible.

Why do people keep repeating this falsehood?

https://www.nytimes.com/roomfordebate/2015/04/16/what-are-co...

Per SCOTUS in US v. Hobby Lobby:

> While it is certainly true that a central objective of for-profit corporations is to make money, modern corporate law does not require for-profit corporations to pursue profit at the expense of everything else, and many do not do so. For-profit corporations, with ownership approval, support a wide variety of charitable causes, and it is not at all uncommon for such corporations to further humanitarian and other altruistic objectives. Many examples come readily to mind. So long as its owners agree, a for-profit corporation may take costly pollution-control and energy-conservation measures that go beyond what the law requires. A for-profit corporation that operates facilities in other countries may exceed the requirements of local law regarding working conditions and benefits. If for-profit corporations may pursue such worthy objectives, there is no apparent reason why they may not further religious objectives as well.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#77

Earlier quoted context omitted.

> Nobody can prove that. It's always listening and you have to assume always recording and transmitting Uh... packet analyzers, IP logs, bandwidth monitoring tools etc... If instead of transmitting occasional bursts of data when you say the wake word it's been sending back tens of megabytes an hour, or tens to hundreds of megabytes a day, you can go "hey, it's probably transmitting everything it hears". There are peo…

Which nobody can do. It is encrypted and unless the device accept invalid certs, they can queue up, compress, batch upload any data they want. They control the security, not the end-luser.

We know how much storage is on the device - we could tell thru network monitoring if they were actually doing this - there is just enough smarts in the device to only turn on the recordings when the wake word is spoken - thats not being said a malicious player wouldnt hack it, and insert their own code to listen all the time - but based on the evidence, I don't think amazon is that player.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#78

Earlier quoted context omitted.

1) Nobody can prove that. It's always listening and you have to assume always recording and transmitting. 2) My phone is a $12 throw away that speaks voice and sms (text). 3) Loose lips sink ships.

If we are playing the "you can't prove that" game, then you also can't prove that your $12 throw away phone isn't always recording, or that you new kitchen countertop doesn't have a recording device embedded in it, or that the maker of whatever device you are using to type that comment isn't breaking a plethora of laws to record everything you type or say or do around that device at any time.

When my throw away phone is transmitting, it gets warm. I also set it next to an amplifier and I can actually hear it bleed into the amp when it chats with the cell site. I can even tell a couple of seconds ahead of time when I am getting a text or a phone call.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#79
post #17

I am baffled by how many people have no problems adding always listening and recording Google and Facebook devices to their living rooms. Some are considered tech people who should know stuff like this could happen, but they just don't care or don't think it will happen to them. Somewhere there is an ex-Stasi officer who is thinking "I wish we were that good and had people fooled to voluntarily install listening devi…

1) It's always listening for a keyword, and then it starts recording. It's a voice interface for a computer. 2) Your phone is doing the same thing except for it follows you around everywhere you go and records your map location, what apps you use, who you are talking to and what your web searches are. Your phone isn't recording just what you say...its recording what you do and where you do it and when you do it. It's…

You can opt out of basically every Google login/tracking in Android, except the Play store. I know because I'm logged out of everything and I disable location services. Google Maps keeps working.

What I don't understand is why they have to store voice recordings instead of deleting them once they understand the vocal command. There could be a number of reasons and I don't like any of them.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#80
post #74

Earlier quoted context omitted.

Which nobody can do. It is encrypted and unless the device accept invalid certs, they can queue up, compress, batch upload any data they want. They control the security, not the end-luser.

Encrypted or not, an audio stream should not be difficult to identify.

If they batch compress and upload, it wont be a stream. It could be aes-256 lzma2 compressed chunks. Using the right codec, they could likely upload a hour of audio in a few hundred kbytes. I have seen some demos of highly bw optimized codecs.

Here are some staring points. [1] I would go with Opus. My voice chat server uses that.

[1] - https://stackoverflow.com/questions/167533/best-voice-compre...

Post reply on HN